Labels

Monday, April 26, 2021

Planning for a big change in the network

 There have been some happenings going on at the house that might involve some additions.  To that extent, the location of most of my networking equipment is probably going to change so that other work can be done to the older parts of the house.  I am thinking of moving my main router and switch to the new addition and along with it, most of the Ethernet connections for the old portions of the house and the new portions of the house.  I also have to bear in mind that I cannot use the main channel through the old part of the house anymore, I have to deal with other ways of getting the information through.

So, in retrospect, I am happy that I have learned some things about vlans, because they are going to become very handy in the near future unless I can find a different route for cabling.  That being said, I am also going to have to pull Ethernet cables from locations where they are no longer esthetically appealing, meaning I can't just have cables dangling from the ceiling in my computer room because that room will probably go away.  The rooms will change in what they are going to be used for.  I am planning on moving my Tool Room elsewhere in the house to accommodate more space to do what I wish to do.  Overall, I may end up with a box of Ethernet cables that I no longer need and go back to some shared trunk lines that make more sense.

I intend to have fun with these changes (should they happen) but at the same time I have to be conscious that the changes may have an affect on systems that I already have up and running.

Sunday, March 21, 2021

Tips #10 - Network Setup for Raspberry Pi Static Experiments

After some time working with Raspberry Pis (RPi) I have been able to figure out the kind of network setup that makes sense when you develop over a period of time.  Here are some particulars of what I have found:
  • Use of a Managed Switch with a trunk line to all of the vlans in the house saves a lot of running around.
  • Use of Tasmota controlled extension cables can give you control of power to the RPis in case there are moments when you only want to concentrate on specific RPis for an experiment
  • The managed switch on the desk where you wire up experiments gives you extra network connections when needed.
  • The key is to be able to work on just what you want without having other thins on when you don’t need them to be on.

Tips #9 - The Sacrificial Port and Admin vlans

One thing I have discovered in my attempt to be secure is the use of Admin vlans.  An Admin vlan is a vlan that you use to limit changes to your network.  This is for internal network infrastructure protection. There are a couple of important points about this:
  • Each router, Managed Switch, and Type 1 hypervisor that you have in your network is configured so that changes can only be made from the Admin vlan.
  • All ACs/Rules setup in the network enforce the Admin vlan to be separate from all others and enforces the items in this list.
  • You set up connections throughout the network so that you have to be physically connected to an Admin vlan port to make changes to any infrastructure elements in the network.
  • We have a port on each device dedicated to the Admin vlan, but the Admin vlan is allowed to traverse between devices only on Trunk lines and those lines are physically protected as much as possible.
  • All connections on the Admin vlan devices have to be encrypted; this is a zero trust approach.
  • Encrypted Certs are controlled by a local Certificate Authority (CA) that is usually offline.
  • The Admin vlan port is called the Sacrificial Port because that port is only used for the purpose of getting to the Admin vlan.
  • The sacrificial port is protected with an 802.1x/Radius connection by MAC address; if you aren’t supposed to be there you shouldn’t be allowed to get in.
  • The sacrificial Port is also there to make sure you can still control infrastructure devices if part of the network becomes unresponsive.
  • The Sacrificial Port is also protected by a keyed Ethernet dust plug (suggest the color Red); key is necessary to take the plug out of the device.

Monday, March 15, 2021

Changeover of Ubuntu Server to Proxmox Box

 I have been wanting to try my hand at a Type 1 hypervisor for a while but it was too expensive.  I looked at ESXi, but decided that each change of the software meant a world of hurt for the VMs that would be running.  I do like to use KVM and have wanted to learn LXC containers, so I decided to change out the Ubuntu Server and go with Proxmox.

I changed the HW for the Proxmox server to have a 1TB SSD, repurposed the 4TB spinner from the Ubuntu Server to use, and reconnected the DVD drive.  I did a fresh install from the Proxmox 6.3-1 iso that I downloaded from the site and came up running very quickly.  I then added a number of OS isos, including CentOS, Ubuntu, and Fedora.  I was able to quickly spin up Ubuntu and start working on the challenge of other VMs and LXCs.

I connected the GUI/SSH port of the Proxmox to my admin vlan and ran the first Ubuntu VM on my Pers vlan.  So far so good.

Sunday, February 21, 2021

HW #1 - TiVo over MoCA Peculiarities

 Over time, I have learned some peculiarities about the TiVo system:

  • When I originally used the TiVo Bolt with a couple of TiVo Minis, I had all connections over Ethernet.  That worked out fine, but I did discover that the Minis did not let go of their tuners which resulted in an enormous amount of traffic over the ethernet lines.  Even placing the equipment on a separate vlan only partially solved the problem.
  • Early on you were able to select the TiVo button on the Minis and cause the Mini to release its hold on the TiVo Bolt tuner.
  • When I had the equipment blow out due to a power surge, I opted to get the TiVo Edge.  Updating the Edge and the Minis brought me into a condition in which I was unable to release the Minis from the Edge tuner.  I have since learned that they changed the TiVo Minis and thus they might be able to release the tuners somehow.
  • Because of the amount of traffic for the TiVos on Ethernet, I decided to run the connections over MoCA.  I have a Verizon FIOS ONT that I connect to and ended up putting the Edge and the Minis on channel 15 in order to get it to work.  This was acceptable and now the traffic between the Minis and the Edge are isolated from my Ethernet, or so I thought.
  • Since I needed to setup the TiVo Edge as a MoCA bridge, I was surprised to learn that the Ethernet connection to the Edge was absolutely hammering the unmanaged Ethernet switch it was plugged into.  This is to be expected since apparently the TiVo minis do not go directly to the TiVo Edge but actually go out the bridge, bounce off of the Ethernet switch and back to the TiVo Edge.  Normally, only the port that the TiVo Edge is plugged into shows any traffic (flashing LED).  Without the Ethernet switch, there would be a lot of traffic to deal with.


Friday, February 19, 2021

Tips #8 - Using a Router as an Access Point with Multiple SSIDs

In the course of helping someone out on Reddit about their setup, it occurred to me that there have been multiple instances of people asking about using an old router as an access point.  It also helps if you consider the advice peppered with multiple VLANs and multiple SSIDs.  Lets assume you have a Wi-Fi router and want to use another router as an access point (lets call it AP).  Further, lets assume that you have two VLANs you wish to use.  Here are some things to consider (not in any particular order):

  • You probably will want to do a Wi-Fi survey to see where your neighbors are parked on the Wi-Fi spectrum and figure out from there how you want to minimize interference - I recommend Acrylic Wi-Fi as the tool to use, there is a free version.  There are also some tools under Kali Linux as well.
  • If you have a mobile device, you will generally want to seamlessly switch between Wi-Fi sources.  To do this, you are going to want to have the Wi-Fi router and AP on different Wi-Fi channels.  So, as a general rule walking around your house will cause your cell phone to connect to the Wi-Fi source with the strongest signal. If on the other hand the one SSID is on the same Wi-Fi channel on both devices you could wind up with them interfering with each other.
  • We will assume you have VLANs that you are using to separate the networks.
  • I make it a point to have different SSIDs based on the vlan it is connected to, so if you have 2 VLANs, you should use 2 SSIDs (different names). 
  • Always make sure that the SSIDs have the same passphrase across the devices, but use two different passphrases for two different SSIDs. Then the SSIDs will be cryptographically separate from each other.
  • Most smart home devices will use the 2.4GHz spectrum, rarely will you see it connect to 5.4GHz, so you could in effect only need the 2.4GHz spectrum for the smart devices and that may influence your choice for how you set up each SSID.
  • If you have smart TVs, I would try to use Ethernet as much as is possible to connect them; video chews up a lot of Wi-Fi bandwidth.
  • Don't setup the AP in bridge mode; that implies that you are going through the WAN port. There is no need to do that if you are using it as an access point. Connect the cable from a port on LAN side of the router to one of the ports on the Linksys LAN side. This cable should be designated as a trunk line, i.e. it will be carrying multiple VLANs.  By doing it that way, you will keep the one SSID to one vlan mantra unaltered.  Setup the VLANs accordingly.
  • In the AP vlan setup do not setup a DHCP server, but use a DHCP relay mode instead, and point the relay address to the router vlan IP address. That way a connection to the AP will use the router to get it's IP address (which also means it will get it's DNS info from the same source).

This is simple but effective and I have used this approach many times to success.

Wednesday, February 17, 2021

Zone Based Routing and the Edgerouter-X

I am attempting to use an Edgerouter-X (ERX1 for short) to provide specific, controlled access between vlans and certain equipment.  The first use case will be entirely composed of port forwarding, but between multiple vlans.  First case is to define what I mean by setup:

The New Setup for vlans on ERX1

  • ERX1-1 will be connected to Media Router for access to the Media vlan
  • ERX1-2 will be connected to Main Switch for access to the Admin vlan for configuration
  • ERX1-5 will be connected to Main Switch for access to other vlans as a trunk line
  • ERX1 vlans will be setup as normal, always getting IP from DHCP and doing DHCP Remote to keep the gateways pure

The following Zones will be defined:

  • Local (ERX1 itself)
  • Admin
  • Media
  • Personal
  • IOT
  • LAN3
  • DMZ

The following special defined accesses are:

  • Port 8123 of the HA-IOT server on IOT vlan <-> every IP on LAN3 vlan
  • HA-IOT server on IOT vlan <-> data server ports on Personal vlan
  • ports for Plex server on Personal vlan <-> every IP on the Media vlan
  • ports for Plex server on Personal vlan <-> every IP on the LAN3 vlan
  • every IP on the Media vlan <-> data server ports on Personal vlan
  • Docker container ports in the Development vlan <-> the MQTT server on the HA-IOT server in the LAN3 vlan
  • every IP on the LAN3 vlan <-> Media equipment ports on the Media vlan
  • specific IPs on the DMZ <-> data server ports on Personal vlan
  • Some of these alternate connections are going to require the device to be on the same subnet

Group Definitions needed:

  • port 8123 on HA-IOT Server on IOT vlan
  • data server ports on Personal vlan
  • Plex server ports on Personal vlan
  • MQTT server port on IOT vlan 
  • Media equipment ports on Media vlan
  • Specific IPs on the DMZ vlan

The first items on the ERX1 that need to be completed for setup include resetting the ERX1 to default, setting up an initial default router setup with two subnets, defining the Admin vlan, setting up the main switch to accommodate connection to the Admin vlan and to the Media vlan (with the WAN port).  From there I should be able to update the ERX1 as I go.